QID 731184

Date Published: 2024-02-29

QID 731184: Joomla Cross-Site Scripting (XSS) Vulnerability (20240205)

Joomla is a free and open-source content management system written in PHP. It uses object oriented programming techniques and is built on a model-view-controller web application framework. It includes features such as page caching, RSS feeds, printable versions of pages, news flashes, blogs, polls, search, and support for language internationalization.

CVE-2024-21726: Joomla versions 3.7.0-3.10.14-elts, 4.0.0-4.4.2, 5.0.0-5.0.2 is vulnerable to XSS vulnerability.

Affected Version:
Joomla! CMS versions from 3.7.0 prior to 3.10.15-elts
Joomla! CMS versions from 4.0.0 prior to 4.4.3
Joomla! CMS versions from 5.0.0 prior to 5.0.3

Fixed Version:
Upgrade to version 3.10.15-elts, 4.4.3 or 5.0.3

QID Detection Logic(Unauthenticated):
QID checks for the Vulnerable version of Joomla.

Successful exploitation of this vulnerability may allow an attacker in inadequate content filtering leads to XSS vulnerabilities in various components.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    The vendor has released a patch in Joomla versions 3.10.15-elts, 4.4.3 or 5.0.3 to remediate this vulnerability.
    Vendor References

    CVEs related to QID 731184

    Software Advisories
    Advisory ID Software Component Link
    20240205 URL Logo developer.joomla.org/security-centre.html